Impact
InstantCMS versions earlier than 2.18.2 allow an attacker with authenticated access to upload a malicious component. While the component itself is not installed, it can be placed in the upload folder and executed by exploiting a custom .htaccess file that enables PHP parsing. The vulnerability gives an attacker the ability to run arbitrary PHP code, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
The affected product is InstantCMS from instantsoft:icms2. All releases prior to 2.18.2 are vulnerable. Version 2.18.2 includes a fix.
Risk and Exploitability
The CVSS score is 5.5, indicating a moderate severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote authenticated access and the ability to upload files. The attacker can bypass normal upload restrictions by placing a tampered .htaccess file in the upload directory, which then allows execution of the uploaded PHP payload. Given the authentication requirement and lack of widespread exploitation indicators, the risk is considered moderate but should be addressed promptly.
OpenCVE Enrichment